Provider-neutral architecture

One control model. Multiple enforcement planes.

The launch path uses Cloudflare for SaaS. Envoy and Coraza preserve first-party policy, telemetry and an incremental path toward Native Edge.

Operational viewIllustrative flow. No customer data.
What the current evidence supports

The control plane compiles logical intent. Provider adapters translate it without changing cases, safety contracts, evidence or customer workflows.

GoTe now

GoTe nowGoTePrivate beta · operator-assisted
Traffic
Checking current route
Protection
Unknown
Runtime
Unknown
Scope
Not verifiable
Traffic proof until
Not verifiable

Current state is shown only after a fresh, schema-validated snapshot is loaded.

Open status evidence
01

Platform capabilities

These cards describe product scope. Current delivery stage, runtime health, scope and freshness are reported separately from the validated public snapshot above.

01

Global ingress

Exact hostnames, managed certificates and global edge protection form the launch route.

Platform · planned
02

AegiFlow Edge

Envoy and Coraza provide service-specific inspection and future provider portability.

Platform · implemented
03

PostgreSQL control plane

A modular Go application, durable jobs and RLS keep the control plane understandable and testable.

Platform · implemented
04

Open integration plane

Sigma and STIX content, customer SIEM/DFIR tools and bounded scanners contribute evidence without becoming request-path dependencies.

Platform · planned
02

How you use it in an operating workflow

The visitor path remains short. Configuration, verification and rollback stay visible to the operator at every stage.

Fast request pathParallele AnalyseEvidence before promotion
  1. 01

    Local decision

    The edge enforces the last valid signed policy.

  2. 02

    Durable control

    The control plane records cases, workflows and provider reconciliation.

  3. 03

    Independent recovery

    Continuity storage must survive both edge and origin failure.

03

The interface explains what is known, unknown and required

AegiFlow does not turn missing evidence into a reassuring zero. Every state links to its source, freshness and next action.

Delivery stage
Planned, implemented, verified, activatable or active.
Runtime health
Healthy, degraded, stale, unknown or unavailable — independently of delivery stage.
Evidence
Source, timestamp, scope and last successful verification.
Action
The responsible party, exact change and expected impact.
Way back
Rollback instructions are defined before an active change.
04

In depth

How this capability behaves in production — grounded in the platform's documented, current operation.

Control plane and data plane, deliberately apart

The path a visitor's request takes is short and local: global ingress, the AegiFlow edge, your origin. Everything else — correlation, threat feeds, dashboards, reports — runs asynchronously in the control plane and can degrade without touching traffic.

Private origins and outbound-only plumbing

Protected origins can stay entirely private, reachable only over mutual TLS from the AegiFlow edge, while the platform's own connections are outbound-only tunnels. There is no inbound port waiting to be found, and the provider-neutral edge preserves an exit path from any single vendor.

Start without changing traffic. Activate only measured controls.

Ownership, certificate, origin health and rollback must pass before traffic protection changes.

Discuss an architecture review